First published: Tue Nov 12 2024(Updated: )
A stack-based buffer overflow vulnerability [CWE-121] in FortiManager, FortiAnalyzer and FortiAnalyzer-BigData CLI may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | >=6.2.0<7.2.6 | |
Fortinet FortiAnalyzer | >=7.4.0<7.4.3 | |
Fortinet FortiAnalyzer BigData | >=6.2.1<7.2.8 | |
Fortinet FortiAnalyzer BigData | =7.4.0 | |
Fortinet FortiManager | >=6.2.0<7.2.6 | |
Fortinet FortiManager | >=7.4.0<7.4.3 | |
Fortinet FortiAnalyzer | >=7.4.0<=7.4.2 | |
Fortinet FortiAnalyzer | >=7.2.0<=7.2.5 | |
Fortinet FortiAnalyzer | >=7.0 | |
Fortinet FortiAnalyzer | >=6.4 | |
Fortinet FortiAnalyzer | >=6.2 | |
Fortinet FortiAnalyzer | =. | |
Fortinet FortiAnalyzer | =. | |
Fortinet FortiAnalyzer | >=7.0 | |
Fortinet FortiAnalyzer | >=6.4 | |
Fortinet FortiAnalyzer | >=6.2 | |
Fortinet FortiManager | >=7.4.0<=7.4.2 | |
Fortinet FortiManager | >=7.2.0<=7.2.5 | |
Fortinet FortiManager | >=7.0 | |
Fortinet FortiManager | >=6.4 | |
Fortinet FortiManager | >=6.2 |
Please upgrade to FortiAnalyzer-BigData version 7.4.1 or above Please upgrade to FortiAnalyzer-BigData version 7.2.8 or above Please upgrade to FortiManager version 7.4.3 or above Please upgrade to FortiManager version 7.2.6 or above Please upgrade to FortiAnalyzer version 7.4.3 or above Please upgrade to FortiAnalyzer version 7.2.6 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31496 is categorized as a critical vulnerability due to its potential for arbitrary code execution via crafted CLI requests.
To fix CVE-2024-31496, upgrade FortiManager or FortiAnalyzer to versions 7.4.3, 7.2.6, or the respective recommended versions for your software.
CVE-2024-31496 affects FortiManager, FortiAnalyzer, and FortiAnalyzer-BigData across various versions.
No, an attacker must have privileged access to exploit CVE-2024-31496 and execute unauthorized commands.
CVE-2024-31496 is a stack-based buffer overflow vulnerability classified under CWE-121.